Skip to content

Commit 146f0bf

Browse files
Sync EUVD catalog: Thu Jun 18 01:01:07 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 391e6cd commit 146f0bf

735 files changed

Lines changed: 41944 additions & 1387 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/05/EUVD-2026-26489.json

Lines changed: 37 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,21 +3,54 @@
33
"enisaUuid": "69905fd3-eb04-357f-8742-dcc47103f73b",
44
"description": "An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.",
55
"datePublished": "May 1, 2026, 12:00:00 AM",
6-
"dateUpdated": "May 1, 2026, 8:07:56 AM",
6+
"dateUpdated": "Jun 17, 2026, 12:37:03 AM",
77
"baseScore": 8.0,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
1010
"references": "https://bugs.launchpad.net/ironic-python-agent/+bug/2148310\nhttps://github.com/openstack/ironic-python-agent/blob/236b33abffe6688afc39c21e351cc3889b3db2dd/ironic_python_agent/efi_utils.py#L134-L139\n",
11-
"aliases": "CVE-2026-43003\n",
11+
"aliases": "PYSEC-2026-205\nGHSA-rmxr-45gj-889w\nCVE-2026-43003\n",
1212
"assigner": "mitre",
13-
"epss": 0.0,
13+
"epss": 0.54,
1414
"enisaIdProduct": [
15+
{
16+
"id": "12de8033-9421-3f2b-bf54-96dd358df433",
17+
"product": {
18+
"name": "ironic-python-agent",
19+
"vendor": {
20+
"name": "OpenStack"
21+
}
22+
},
23+
"product_version": "0 <10.2.3"
24+
},
25+
{
26+
"id": "2ab11382-dfa5-3150-85c0-4dd92b7aefe2",
27+
"product": {
28+
"name": "ironic-python-agent",
29+
"vendor": {
30+
"name": "OpenStack"
31+
}
32+
},
33+
"product_version": "11.0.0 <11.2.1"
34+
},
1535
{
1636
"id": "3e2da637-6d20-37e5-bd51-89a67cdadff4",
1737
"product": {
18-
"name": "ironic-python-agent"
38+
"name": "ironic-python-agent",
39+
"vendor": {
40+
"name": "OpenStack"
41+
}
1942
},
2043
"product_version": "1.0.0 \u226411.5.0"
44+
},
45+
{
46+
"id": "e8597a1e-f101-3d7d-8851-f1a6e880fb6d",
47+
"product": {
48+
"name": "ironic-python-agent",
49+
"vendor": {
50+
"name": "OpenStack"
51+
}
52+
},
53+
"product_version": "11.3.0 <11.5.1"
2154
}
2255
],
2356
"enisaIdVendor": [

advisories/2026/05/EUVD-2026-31079.json

Lines changed: 103 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,112 @@
33
"enisaUuid": "da6d93bc-557b-311c-ba88-c9edaf40cf15",
44
"description": "A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.",
55
"datePublished": "May 20, 2026, 9:00:42 AM",
6-
"dateUpdated": "May 20, 2026, 1:41:09 PM",
6+
"dateUpdated": "Jun 17, 2026, 1:55:43 AM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
10-
"references": "https://access.redhat.com/security/cve/CVE-2026-9064\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2480093\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:26452\nhttps://access.redhat.com/errata/RHSA-2026:26456\nhttps://access.redhat.com/errata/RHSA-2026:26457\nhttps://access.redhat.com/errata/RHSA-2026:26458\nhttps://access.redhat.com/errata/RHSA-2026:26459\nhttps://access.redhat.com/errata/RHSA-2026:26460\nhttps://access.redhat.com/errata/RHSA-2026:26461\nhttps://access.redhat.com/errata/RHSA-2026:26464\nhttps://access.redhat.com/security/cve/CVE-2026-9064\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2480093\n",
1111
"aliases": "CVE-2026-9064\nGHSA-7r3c-wfgh-x96c\n",
1212
"assigner": "redhat",
13-
"epss": 0.0,
14-
"enisaIdProduct": [],
15-
"enisaIdVendor": []
13+
"epss": 0.45,
14+
"enisaIdProduct": [
15+
{
16+
"id": "01b8ccce-5441-3c68-bae9-5a5b800560b3",
17+
"product": {
18+
"name": "Red Hat Enterprise Linux 10",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
22+
},
23+
"product_version": "patch: 0:3.2.0-7.el10_2"
24+
},
25+
{
26+
"id": "235e237e-3840-3155-846e-b37572c1b455",
27+
"product": {
28+
"name": "Red Hat Directory Server 11.9 for RHEL 8",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
32+
},
33+
"product_version": "patch: 8100020260601104139.37ed7c03"
34+
},
35+
{
36+
"id": "4038b9a3-ce4f-3021-b91a-da2b9864ecde",
37+
"product": {
38+
"name": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
42+
},
43+
"product_version": "patch: 8060020260609102416.824efc52"
44+
},
45+
{
46+
"id": "5ecb38b4-8547-32e2-b25b-90f9a2bb9658",
47+
"product": {
48+
"name": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
52+
},
53+
"product_version": "patch: 8060020260609102416.824efc52"
54+
},
55+
{
56+
"id": "64fbfc85-59dd-341e-8fed-496da75f9cb7",
57+
"product": {
58+
"name": "Red Hat Enterprise Linux 8",
59+
"vendor": {
60+
"name": "Red Hat"
61+
}
62+
},
63+
"product_version": "patch: 8100020260601102239.25e700aa"
64+
},
65+
{
66+
"id": "745c862c-f7a9-331d-a632-dcec92271a46",
67+
"product": {
68+
"name": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
69+
"vendor": {
70+
"name": "Red Hat"
71+
}
72+
},
73+
"product_version": "patch: 0:2.4.5-25.el9_4"
74+
},
75+
{
76+
"id": "7b6bc5cd-14c6-3908-970c-2a3f17a10721",
77+
"product": {
78+
"name": "Red Hat Directory Server 11.5 E4S for RHEL 8",
79+
"vendor": {
80+
"name": "Red Hat"
81+
}
82+
},
83+
"product_version": "patch: 8060020260609102432.0ca98e7e"
84+
},
85+
{
86+
"id": "95127ee6-8bee-3d3c-9c5d-f81c8b9e8dfe",
87+
"product": {
88+
"name": "Red Hat Enterprise Linux 10.0 Extended Update Support",
89+
"vendor": {
90+
"name": "Red Hat"
91+
}
92+
},
93+
"product_version": "patch: 0:3.0.6-18.el10_0"
94+
},
95+
{
96+
"id": "d1932802-5d2d-337e-ba82-b675d404b8f8",
97+
"product": {
98+
"name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
99+
"vendor": {
100+
"name": "Red Hat"
101+
}
102+
},
103+
"product_version": "patch: 0:2.2.4-18.el9_2"
104+
}
105+
],
106+
"enisaIdVendor": [
107+
{
108+
"id": "45971eb6-2eae-3712-bbcf-e7950004ea09",
109+
"vendor": {
110+
"name": "Red Hat"
111+
}
112+
}
113+
]
16114
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55626",
3+
"enisaUuid": "7b4b0652-610c-3331-b14c-82f66040e316",
4+
"description": "Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery.\n\nThis issue affects Skyline WP: from n/a through 1.0.10.",
5+
"datePublished": "Jun 17, 2026, 6:35:42 PM",
6+
"dateUpdated": "Jun 17, 2026, 6:35:42 PM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
10+
"references": "https://patchstack.com/database/wordpress/theme/skyline-wp/vulnerability/wordpress-skyline-wp-theme-1-0-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-34810\n",
11+
"aliases": "GHSA-29p2-vxjx-v5jw\nCVE-2024-34810\n",
12+
"assigner": "Patchstack",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "444be066-d275-3d42-b778-7bf58a9e5c36",
17+
"product": {
18+
"name": "Skyline WP",
19+
"vendor": {
20+
"name": "Extend Themes"
21+
}
22+
},
23+
"product_version": "n/a \u22641.0.10"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "27ce99f4-d221-39b7-9a18-04f1dfd563e0",
29+
"vendor": {
30+
"name": "Extend Themes"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55627",
3+
"enisaUuid": "6d1f906c-18d9-354c-acd5-855b2f597962",
4+
"description": "Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.",
5+
"datePublished": "Jun 17, 2026, 6:35:42 PM",
6+
"dateUpdated": "Jun 17, 2026, 6:35:42 PM",
7+
"baseScore": 7.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
10+
"references": "https://patchstack.com/database/wordpress/theme/my-flatonica/vulnerability/wordpress-my-flatonica-theme-0-0-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-49269\n",
11+
"aliases": "GHSA-993p-g2jw-369f\nCVE-2024-49269\n",
12+
"assigner": "Patchstack",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "ab1ef685-2b67-30b6-b56b-9453d06dcbf6",
17+
"product": {
18+
"name": "my flatonica",
19+
"vendor": {
20+
"name": "mythemes"
21+
}
22+
},
23+
"product_version": "n/a \u22640.0.8"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "503a6978-793f-3035-9151-1971ba726f41",
29+
"vendor": {
30+
"name": "mythemes"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55628",
3+
"enisaUuid": "d3729fcb-2465-35b6-ade1-7714ee9474c2",
4+
"description": "Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.",
5+
"datePublished": "Jun 17, 2026, 6:35:42 PM",
6+
"dateUpdated": "Jun 17, 2026, 6:35:42 PM",
7+
"baseScore": 9.9,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
10+
"references": "https://patchstack.com/database/wordpress/theme/grip/vulnerability/wordpress-grip-theme-1-0-9-arbitrary-plugin-activation-deactivation-to-rce-vulnerability?_s_id=cve\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-52488\n",
11+
"aliases": "GHSA-xpxj-gv5m-476x\nCVE-2024-52488\n",
12+
"assigner": "Patchstack",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "cf0de260-1667-389e-8603-61ce5fd6dd7d",
17+
"product": {
18+
"name": "Grip",
19+
"vendor": {
20+
"name": "Candid themes"
21+
}
22+
},
23+
"product_version": "n/a \u22641.0.9"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "94ce8204-c877-377e-9c68-6bcbfba96514",
29+
"vendor": {
30+
"name": "Zidithemes"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55629",
3+
"enisaUuid": "7fe8198e-0180-37e0-a3c0-be7d6e8a41cc",
4+
"description": "Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Startupzy: from n/a through 1.1.1.",
5+
"datePublished": "Jun 17, 2026, 6:35:41 PM",
6+
"dateUpdated": "Jun 17, 2026, 6:35:41 PM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
10+
"references": "https://patchstack.com/database/wordpress/theme/startupzy/vulnerability/wordpress-startupzy-theme-1-1-1-broken-access-control-vulnerability?_s_id=cve\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-33685\n",
11+
"aliases": "GHSA-v42c-gm96-j95x\nCVE-2024-33685\n",
12+
"assigner": "Patchstack",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "ae3799d0-9c2a-3421-adc4-9c58a39e3578",
17+
"product": {
18+
"name": "Startupzy",
19+
"vendor": {
20+
"name": "Jegstudio"
21+
}
22+
},
23+
"product_version": "n/a \u22641.1.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "2afd83cb-cf44-3051-b1cf-2ca41fbfb411",
29+
"vendor": {
30+
"name": "Jegstudio"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55630",
3+
"enisaUuid": "6684fe32-273e-3d3c-b553-37716c20b728",
4+
"description": ": Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Social Media & Share Icons: from n/a through 2.8.6.",
5+
"datePublished": "Jun 17, 2026, 6:35:41 PM",
6+
"dateUpdated": "Jun 17, 2026, 6:35:41 PM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
10+
"references": "https://patchstack.com/database/wordpress/plugin/ultimate-social-media-icons/vulnerability/wordpress-social-media-share-buttons-social-sharing-icons-plugin-2-8-6-broken-access-control-vulnerability?_s_id=cve\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-31435\n",
11+
"aliases": "GHSA-36cv-2jhv-qv9f\nCVE-2024-31435\n",
12+
"assigner": "Patchstack",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "f8483075-15b4-3028-a1c1-cafb721868ef",
17+
"product": {
18+
"name": "Social Media & Share Icons",
19+
"vendor": {
20+
"name": "Inisev"
21+
}
22+
},
23+
"product_version": "n/a \u22642.8.6"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "4196f4d5-7bbd-3572-81e8-c0e0d41cf21d",
29+
"vendor": {
30+
"name": "Inisev"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55631",
3+
"enisaUuid": "409950cd-e300-3373-b24c-0b63b322ce42",
4+
"description": "Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Shareaholic: from n/a through 9.7.11.",
5+
"datePublished": "Jun 17, 2026, 6:35:41 PM",
6+
"dateUpdated": "Jun 17, 2026, 6:35:41 PM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
10+
"references": "https://patchstack.com/database/wordpress/plugin/shareaholic/vulnerability/wordpress-shareaholic-plugin-9-7-11-broken-access-control-vulnerability?_s_id=cve\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-24709\n",
11+
"aliases": "CVE-2024-24709\nGHSA-h7v4-478g-484w\n",
12+
"assigner": "Patchstack",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "a2bef96d-203e-3d23-873c-2dd188c8b4a0",
17+
"product": {
18+
"name": "Shareaholic",
19+
"vendor": {
20+
"name": "Shareaholic"
21+
}
22+
},
23+
"product_version": "n/a \u22649.7.11"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "1fbef110-e38b-37dc-a52d-148edbff5294",
29+
"vendor": {
30+
"name": "Shareaholic"
31+
}
32+
}
33+
]
34+
}

0 commit comments

Comments
 (0)